Sign in

Dino A. Dai Zovi

@ddz.bsky.social
2K followers 108 following 132 posts

I drink amari and I know things. $ddz LMDDGTFY: duckduckgo.com/?q=dino+dai+zovi NYC/BK

PostsRepliesMedia
Reposted by Dino A. Dai Zovi
Kendra Albert @kendraserra.bsky.social · 30/03/2025
New users, on Signal, you can mute chats for a period or permanently. No notifications but you can still see if there are unread messages. On desktop: in that chat, go to Group Settings, then Notifications. On iPhone: in that chat, click on the name at the top, then go to Sounds & Notifications.
46513
Dino A. Dai Zovi @ddz.bsky.social · 30/03/2025
"Life Safety building automation is pretty awesome. 👏"
030
Reposted by Dino A. Dai Zovi
Angie Jones @angiejones.tech · 30/03/2025
Excellent writeup on how MCP future-proofs API integrations ~ @stevemanuel.bsky.social docs.mcp.run/blog/2025/03...
docs.mcp.run
MCP: The Differential for Modern APIs and Systems | 🤖
<div style={{
1218
Reposted by Dino A. Dai Zovi
OffensiveCon @offensivecon.bsky.social · 25/03/2025
Our second keynote for Offensivecon 2025 will be Dino Dai Zovi! @ddz.bsky.social
093
Dino A. Dai Zovi @ddz.bsky.social · 30/03/2025
I'll be doing a speaking!
092
Reposted by Dino A. Dai Zovi
4Dgifts @4dgifts.bsky.social · 17/03/2025
Saw this on the other site but I should comment here: Can't remember his hacker handle but I think Pad & Gandalf of 8lgm were arrested the same day in 1991. You may not know it but the entire infosec & software industries owe 8lgm immense gratitude for making vendors accountable for their vulns
096
Reposted by Dino A. Dai Zovi
antirez @antirez.bsky.social · 08/02/2025
We are destroying software: antirez.com/news/145
antirez.com
We are destroying software - <antirez>
1721261
Dino A. Dai Zovi @ddz.bsky.social · 08/02/2025
Exactly this. We should instead be investing that energy into making authentication in our environment unphishable by making it impossible to give away access to an attacker, even if someone actually wanted to.
051
Reposted by Dino A. Dai Zovi
Shell @risu.bsky.social · 08/02/2025
I have never once run a phishing sim. I refuse to use the word. I put it in air quotes and say scam by text or email etc Tech and cyber has been about deflecting blame to anyone else but themselves- which is what sims are. Blaming people when the system they use should protect against issues.
2103
Reposted by Dino A. Dai Zovi
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 31/01/2025
NEW: WhatsApp says it has notified 90 victims, including journalists and members of civil society, that they were targeted with spyware made by Paragon. This is the first time that Paragon is linked to alleged abuse of its products. techcrunch.com/2025/01/31/w...
techcrunch.com
WhatsApp says it disrupted a hacking campaign targeting journalists with spyware | TechCrunch
The Meta-owned company said the campaign was linked to Israeli spyware maker Paragon.
15733
Reposted by Dino A. Dai Zovi
evacide @evacide.bsky.social · 31/01/2025
Meta says almost 100 journalists and activists were targeted with spyware from Israeli company Paragon Solutions using a zero-click vuln in WhatsApp. If you use an iPhone, enabling Lockdown Mode prevents this from working. www.theguardian.com/technology/2...
theguardian.com
WhatsApp says journalists and civil society members were targets of Israeli spyware
Messaging app said it had ‘high confidence’ some users were targeted and ‘possibly compromised’ by Paragon Solutions spyware
7184131
Dino A. Dai Zovi @ddz.bsky.social · 24/01/2025
👋
000
Reposted by Dino A. Dai Zovi
Dennis @dennisf.bsky.social · 22/01/2025
If you're interested in the history of bug bounties, for reasons, this series I did a few years ago with @k8em0.bsky.social @caseyjohnellis.bsky.social @ddz.bsky.social and many others may be of interest. duo.com/decipher/law...
duo.com
Lawyers, Bugs, and Money: When Bug Bounties Went Boom
Bug bounties have grown from a niche idea to encourage independent security research into a massive business and a legitimate career path for bug hunters in less than 15 years. This is the story of th...
53212
Dino A. Dai Zovi @ddz.bsky.social · 19/01/2025
I'm really liking the crisp definitions of and boundaries between product engineering, domain engineering, and infra engineering in this. How much of your security org builds "what any company would need" (infra) vs. "what is unique to this company but shared across the company" (domain) ?
0111
Dino A. Dai Zovi @ddz.bsky.social · 18/01/2025
There are different privacy concerns and approaches for the training phase of AI as well as for the inference phase of using it. It's a good time to be thinking about what the right approaches are for each.
030
Reposted by Dino A. Dai Zovi
Matthew Green @matthewdgreen.bsky.social · 17/01/2025
I wrote a post about how AI will interface with end-to-end encryption. TL;DR maybe not so well! blog.cryptographyengineering.com/2025/01/17/l...
blog.cryptographyengineering.com
Let’s talk about AI and end-to-end encryption
Recently, I came across a fantastic new paper by a group of NYU and Cornell researchers entitled “How to think about end-to-end encryption and AI.” I’m extremely grateful to see t…
1220182
Dino A. Dai Zovi @ddz.bsky.social · 18/01/2025
+1, security product vendors, services companies, *and* internal teams must always operate under the Hippocratic Oath, "First, do no harm."
132
Reposted by Dino A. Dai Zovi
Kevin Collier @kevincollier.bsky.social · 16/01/2025
So phone metadata *is* actually sensitive and important information? So hard to keep this straight.
bloomberg.com
FBI Has Warned Agents It Believes Hackers Stole Their Call Logs
FBI leaders have warned that they believe hackers who broke into AT&amp;T Inc.’s system last year stole months of their agents’ call and text logs, setting off a race within the bureau to protect the ...
742989
Dino A. Dai Zovi @ddz.bsky.social · 16/01/2025
We blogged again! This time about our Data Safety Levels framework, which was inspired by the CDC/WHO Biosafety Levels system and Laboratory Biosafety Manuals. Like biological agents, we also don't want sensitive data to be exposed to humans or escape. code.cash.app/dsl-framework
code.cash.app
Data Safety Levels Framework: The foundation of how we look at data in Block
Block uses the Data Safety Levels (DSL) Framework to evaluate data sensitivity.
053
Dino A. Dai Zovi @ddz.bsky.social · 14/01/2025
This is the way ;)
010
Dino A. Dai Zovi @ddz.bsky.social · 11/01/2025
PRF in WebAuthN is going to enable epic things
1110
Dino A. Dai Zovi @ddz.bsky.social · 10/01/2025
Fraud is such a broad thing, hard to answer. But I think better forms of digital and cryptographic proofs of selective identity information would help. For example, cryptographic proof of personhood, while still remaining anonymous would help reduce amount of bots and such on social media.
131
Dino A. Dai Zovi @ddz.bsky.social · 10/01/2025
That is true that it is not cool, but the shift to EMV also happened in the US with cardholders not being liable for fraudulent charges by law. I'm not sure what the laws were in AU, but wonder if that was only the situation in EU/UK?
000
Dino A. Dai Zovi @ddz.bsky.social · 06/01/2025
Any plans on supporting Confidential VMs (e.g. AWS Nitro Enclave, AMD SEV-SNP, Intel TDX) w/ TamaGo unikernels?
100
Dino A. Dai Zovi @ddz.bsky.social · 01/01/2025
The way that I think about it is that the systems that I think about the security of have grown larger and more complex. Being Security DRI for Square's EMV launch in 2014 was really educational. True to my roots, I found EMV smartcard parsing mem corruption bugs in our firmware before it shipped :)
041
Dino A. Dai Zovi @ddz.bsky.social · 01/01/2025
Well, in the US, cardholders haven't been liable for fraudulent charges since 1974's Fair Credit Billing Act, which meant issuers owned fraud losses. This created the incentive for the EMV liability shift, which was created by contractual agreements between issuers, acquirers, terminal vendors, etc.
100
Dino A. Dai Zovi @ddz.bsky.social · 01/01/2025
The placement of liability for fraudulent credit card charges onto the issuer incentivized the shift to EMV, so we now have smartcards in our wallets and secure elements on our smartphones. Contrast this to the security of authn to way more critical things than buying a coffee.
391
Reposted by Dino A. Dai Zovi
Filippo Valsorda @filippo.abyssdomain.expert · 31/12/2024
Ever wanted to benchmark RSA key generation but found it too slow and variable, like benchmarking a lottery? No? Just me? Well, I nerd-sniped myself into producing average representative inputs that can be used to benchmark, profile, and compare RSA keygen. c2sp.org/CCTV/keygen Happy New Year(?)!
words.filippo.io
Benchmarking RSA Key Generation
RSA key generation is conceptually simple, but extremely tricky. Even benchmarking involves math: we generated a stable but representative “average case” instead of using the ordinary statistical appr...
26613
Reposted by Dino A. Dai Zovi
Matthew Green @matthewdgreen.bsky.social · 29/12/2024
This Salt Typhoon stuff is insane. The entire FISA surveillance infrastructure has been completely owned by China and literally no part of our telecom infrastructure is safe to use without end-to-end encryption.
27892318
Reposted by Dino A. Dai Zovi
Man in Business Suit Levitating @dfeldman.org · 25/12/2024
You’re still arguing about tabs vs. spaces? May I present…
Code written with box characters used on old old software to make fake UIs
15652621266
Dino A. Dai Zovi @ddz.bsky.social · 26/12/2024
Oh, and then try to get people to manually enter PAN+CVV for a CNP (Card Not Present) transaction? If people pay with Apple Pay or something like it, then it also isn't replayable card data and processing it reveals thief's identity. But I'm sure some people will enter their PAN+CVV, some will not.
000
Dino A. Dai Zovi @ddz.bsky.social · 26/12/2024
How exactly would that work and what card or payment data would it compromise? Even with offline auth (not used in the US, but used in other countries), there really isn't anything that can be done with the cryptograms. You can only send them to issuer/acquirer as a merchant and then you are busted.
100
Dino A. Dai Zovi @ddz.bsky.social · 26/12/2024
There are various PCI PTS compliance aspects around the reported version string and requirements for a delta review on changes to anything within the security perimeter. The version string often refers to the functionality within that perimeter, which may not have been where vuln was or was fixed.
000
Dino A. Dai Zovi @ddz.bsky.social · 26/12/2024
Here is an example of various compromises of an Android-based Point-of-Sale system, but note how they describe that they *weren't* able to interfere with anything handled by the secure processor: blog.stmcyber.com/pax-pos-cves...
blog.stmcyber.com
Android-based PAX POS vulnerabilities (Part 1) - STM Cyber Blog
In this article, we present details of 6 vulnerabilities on the Android POS devices made by the worldwide known company PAX Technology.
270
Dino A. Dai Zovi @ddz.bsky.social · 25/12/2024
The above is a stark, stark contrast to the classic magswipe POS machines with a simple magstripe reader attached to a general-purpose Windows host, which sent full swipe track data in the clear to it.
010
Dino A. Dai Zovi @ddz.bsky.social · 25/12/2024
Theoretically possible, but any EMV POS has to meet PCI PIN Transaction Security (PTS), which means that it is effectively a tamper-responsive Hardware Security Module that happens to run an application to accept payments. Payments acceptance state machine is supposed to be on secure co-processor.
320
Dino A. Dai Zovi @ddz.bsky.social · 25/12/2024
The subtle benefit of *minimal* version selection as a systemic damper on software supply chain attacks: "What’s more, the deeper in your dependency tree the library is, the more explicit approvals are required for the library to propagate to your project." matklad.github.io/2024/12/24/m...
matklad.github.io
Minimal Version Selection Revisited
In this post, I want to highlight one aspect of Go-style minimal version selection that I have missed completely at first. Maybe you missed it too?
071
Dino A. Dai Zovi @ddz.bsky.social · 25/12/2024
It turns out that replacing the static payment authz tokens (PAN, CVV) with smartcards that generate non-replayable cryptographic payment authorization messages e2ee'd to the card issuer made infecting points of sale effectively useless.
160
Dino A. Dai Zovi @ddz.bsky.social · 25/12/2024
The transition from static long-term "credentials" (PAN + CVV) to EMV cryptograms generated by smartcards and the continuing transition for online payments are good case studies for how to devalue data to the point of making attacks on processing infra no longer worthwhile. Human authn must be next.
041
Dino A. Dai Zovi @ddz.bsky.social · 23/12/2024
What "works" means for some categories of infosec products: EDR: detects a non-zero number of attacks, doesn't detect an unspecified number of other attacks IAM: provides users access to resources, and also provides it to an unspecified number of other users (possibly malicious) :)
120
Reposted by Dino A. Dai Zovi
Mike Masnick @masnick.com · 20/12/2024
Honestly, the Let's Encrypt folks don't get nearly enough credit for basically protecting the entire fucking internet, by making it absolute bog standard to encrypt everything. It happened so fast and so many people were skeptical.
151247277
Reposted by Dino A. Dai Zovi
Stéphane Taillat @staillat.bsky.social · 20/12/2024
An excellent episode on a topic on which I've given some thoughts in my book with similar conclusions: 1️⃣Targeting TikTok in the name of "national security" avoids addressing the structural problems of unregulated personal data and content moderation.
1155
Dino A. Dai Zovi @ddz.bsky.social · 20/12/2024
The reason why things like algo won't work is that it trades your trackable home IP for a trackable cloud provider IP, which doesn't address privacy goals of not being trackable across different destination sites and visits across time.
010
Dino A. Dai Zovi @ddz.bsky.social · 20/12/2024
One way to get this would be making the first tier a cloud node that you run which runs an Oblivious HTTP or MASQUE proxy (does not terminate TLS) and cycles cloud IPs periodically. The second tier would be a CDN (Cloudflare or Fastly) for performance and obscuring home IP, essentially.
100
Dino A. Dai Zovi @ddz.bsky.social · 20/12/2024
I haven't really sketched it out yet, but the key principle to implement is information splitting by having two tiers. The first knows who you are (sees real IP or has account info), but not the destination of your traffic. The second does not know who you are, but does know destination of traffic.
110
Dino A. Dai Zovi @ddz.bsky.social · 20/12/2024
Sometimes and most likely, yes. I have been meaning to set up some personal infra to do roughly the equivalent of iCloud Private Relay from Linux, but haven't gotten to it yet.
110
Dino A. Dai Zovi @ddz.bsky.social · 20/12/2024
Fair, that is arguably more about privacy than security. For security, modern browser + OS has TLS applied pervasively enough that I don't actually worry about the security of my traffic except by middle-nodes that terminate and re-reestablish TLS.
010
Reposted by Dino A. Dai Zovi
Bob Lord @boblord.bsky.social · 19/12/2024
Directory traversal vulnerabilities have plagued software customers for over two decades. It's time for software companies to step up and eliminate this persistent class of coding error entirely. More info here: buff.ly/3QpbblJ
152